You are never locked out. The lock screen always offers a fallback: "Unlock with PIN", or "Sign in with recovery phrase". The biometric is a local gate, not an encryption key, so your notes are untouched either way.
Then fix the gate. Enrollment is per-device, so a new phone, a fresh browser profile, or a reinstall needs re-enrolling: Settings > Security > "Biometric Lock", disable, then "Enable biometric unlock" again. It also requires "Trust this device" (untrusted sessions clear when the tab closes) and hardware with a platform authenticator (Touch ID, Face ID, Windows Hello). If a password manager like Bitwarden or 1Password pops up instead of the system prompt, dismiss it and retry, or turn off its passkey capture for the site - the app requests the built-in authenticator, but some managers intercept anyway.
// Read the source
THREAT_MODEL.mdLocal phrase-at-rest: biometric and PIN wrappingOur source and documentation are on GitHub, in English.
Help & FAQ
Answers and step-by-step guides: security, sync, pricing, and switching from other apps.
You get an answer in seconds instead of waiting for a reply. Your assistant reads all 92 answers and every import guide at once, so it can combine them, follow up on your question, and explain it in your own words. We never see any of it, because we do not run a chatbot.
Answer my questions about PrivacyNotes using only its help center, its changelog and its security documentation. Start here: https://privacynotes.app/llms-index.txt It lists every question with the page that answers it. Fetch the one or two that match mine. If you can only make one request, fetch https://privacynotes.app/llms-full.txt instead. If you cannot fetch a .txt or .md file, read https://privacynotes.app/help, https://privacynotes.app/changelog and https://github.com/LifetimeLabsDev/PrivacyNotes.app instead. For what changed, or where something moved, fetch https://privacynotes.app/changelog.md. For how the encryption works, what the server can read, or how to check any of it yourself, fetch https://privacynotes.app/docs/index.md and follow it to one of the documents it lists. That index is a router: cite the document, never the index. Rules: - Use only those pages. If they do not answer something, say so instead of guessing. - Never invent a feature, a menu path, a price, or a limit. - End your reply with the "Source:" URL from the page you used, exactly as written. - Answer in the same language as my question. - Never ask me for my recovery phrase, my PIN, or the contents of a note. If no question follows, ask me what I would like to know. My first question:
Never paste your recovery phrase, your PIN, or a note into an AI.